The classic trap
Recital 77 creates a bridge between the AI Act and the upcoming Cyber Resilience Act (CRA): a high-risk AI system that meets the CRA essential cybersecurity requirements is presumed compliant with the AI Act Article 15 cyber requirements. The trap in practice: vendors believe that ticking standard CRA conformity is enough, whereas the recital explicitly requires the cyber risk assessment to also cover AI-specific vulnerabilities (data poisoning, adversarial attacks, evasion, model extraction). The EU AI Office and the national AI market surveillance authority will check that the EU declaration of conformity issued under the CRA actually covers these AI risks, not a generic cyber perimeter.
The blind spots of a CRA assessment applied to an AI system
- Training data poisoning: malicious injection into the training dataset to bias the production model.
- Adversarial attacks: imperceptible perturbations that flip a prediction (medical imaging, credit scoring, biometrics).
- Model stealing via public APIs: reconstructing the model from massive querying.
- Membership inference: an attacker infers whether a person was in the training set, with direct GDPR impact.
- Prompt injection and function hijacking on LLM components embedded in the high-risk system.
- Fundamental rights risks: the recital requires their integration into the cyber assessment, which goes beyond a CISO's usual perimeter.
The consistency test against your EU declaration of conformity
To benefit from the presumption of conformity, your CRA EU declaration must explicitly mention the controls covering AI vulnerabilities. A generic CRA declaration (OS hardening, CVE management, MFA) will not satisfy an AI market surveillance officer: you must trace the specific measures (training pipeline validation, weight signing, adversarial drift monitoring, documented AI red-teaming).
How Luxgap automates this risk
Our Luxgap AI Threat Surface Mapper makes it impossible to confuse a generic CRA conformity with an AI-cyber conformity that holds up before the AI Office. The tool plugs a specialised LLM agent into your MLOps pipeline (MLflow, Vertex AI, Azure ML, SageMaker, Hugging Face Enterprise, GitLab CI/CD) and automatically reconstructs the map of AI-specific attack surfaces, cross-referenced with your existing CRA EU declaration to detect blind spots in real time.
- Automatically detects models deployed in production via your MLflow, Vertex AI or SageMaker registries and assigns each one its AI Act risk category (high-risk Annex III, GPAI, general purpose).
- Scans the training pipeline to identify possible injection points (unsigned external datasets, unpinned PyPI dependencies, pre-trained models downloaded without hash) and alerts on Teams or Slack within 5 minutes.
- Generates an AI-cyber risk assessment report aligned with CRA essential requirements, enriched with MITRE ATLAS vulnerabilities (poisoning, evasion, extraction, inference), ready to annex to your EU declaration of conformity.
- Orchestrates monthly automated AI red-teaming (adversarial examples, prompt injection on LLM components, membership inference) and keeps timestamped execution evidence.
- Produces a cryptographically sealed PDF, enforceable before the EU AI Office and the national market surveillance authority, demonstrating joint coverage of AI Act Article 15 and CRA essential requirements.
- Computes a consistency score between your current CRA EU declaration and the real AI attack surface, with prioritised recommendations.
Available as a complement to a Luxgap CISO or DPO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your actual models, with a free 48-hour blank audit to measure the gap between your current CRA declaration and the AI Act cyber requirements.